Penetration test report
Application & API assessment
1 critical · 1 high · 1 medium · 1 low
- Tenant isolation bypass in the reporting API
- Password reset token does not expire on use
- Role check enforced in the interface but not at the API
- Session cookie missing SameSite attribute